Impact
The vulnerability in Tenable Sensor Proxy permits a remote attacker to execute arbitrary code with elevated privileges by tricking an operator into connecting the sensor to a host under the attacker's control. Exploitation requires user interaction; once the sensor establishes the connection, the attacker gains code execution on the host powering the sensor. This flaw represents a high‑impact remote code execution (CWE‑94).
Affected Systems
Tenable, Inc.’s Sensor Proxy product is impacted. Any deployment running a version earlier than 1.4.2 remains vulnerable. Tenable has released 1.4.2 which addresses the issue; therefore only installations of Sensor Proxy that have not yet applied the 1.4.2 update or a later version remain at risk.
Risk and Exploitability
The CVSS score of 9.3 indicates critical severity. While the EPSS score is not available, the lack of a KEV listing suggests no publicly known exploits are documented yet, but the high score and user interaction requirement mean the threat exists if an operator is present. The attack vector is remote, relying on an operator inadvertently connecting the sensor to a malicious host, which grants the attacker capabilities such as system reconnaissance, data extraction, or further lateral movement. Administrators should treat this as a critical vulnerability requiring immediate action.
OpenCVE Enrichment